Back to all articlesData

Your marketing database has no permission to exist

Chile's data law lands on December 1 and Mexico rewrote its own eighteen months ago. The exposure isn't your cookie banner — it's the audiences you upload to Meta and the WhatsApp list nobody has ever audited.

Talent Warehouse··4 min read
Dimly lit office after midnight: a desk with two monitors showing spreadsheets and an open filing cabinet spilling folders, shot with direct flash and heavy grain.

Chile's Ley 21.719 takes effect on December 1, 2026. Almost nobody on the marketing side has it on a calendar, because it reads like a legal or IT problem. It isn't. It sits squarely on paid media, CRM and contact lists — which is to say, on the budget.

Chile isn't alone. Mexico replaced its entire data protection law on March 20, 2025, effective the next day, and a large share of privacy notices across the region still name INAI — a regulator that no longer exists. If your notice says INAI, it has been wrong for over a year and nobody caught it.

The cookie banner is the easy part

The expensive misunderstanding is assuming compliance means a banner and a checkbox. The banner is the cheapest piece and the least relevant to how your team actually operates.

What changes is that every processing activity now needs a lawful basis you can point to: consent, contract, legal obligation or legitimate interest. "We collected it at a trade show in 2023" is not a lawful basis. "A partner shared it with us" is not either. And "the form said we could contact them" depends entirely on what that form said, which almost nobody can prove two years and four revisions later.

Chilean fines reach 20,000 UTM — roughly US$1.5 million — and for repeated serious violations by large companies, 2% to 4% of annual revenue in Chile. Mexico goes up to 320,000 UMA, about 37 million pesos, doubling when sensitive data is involved. No regulator is going to hand that to the first small business it finds on December 2. But it does change the risk math for anyone signing off on a campaign.

The real exposure is in the audiences you upload

Here's the part nobody wants to open. Every time you push a CSV of emails into Meta to build a Custom Audience or a Lookalike, you are transferring personal data to a third party outside the country for a purpose — advertising — that was almost certainly never disclosed when you collected the address.

  • A customer gave you their email so you could send an invoice. Not to seed a 3% Lookalike.
  • A lead filled in a form to download a PDF. They did not agree to eighteen months of retargeting.
  • A contact came in through an Instagram giveaway whose terms say nothing, because the community manager wrote them at eleven at night.

The same logic applies to the Conversions API. Sending hashed emails server-side is better measurement and solves the browser problem, but it doesn't answer the purpose question. Hashing protects data in transit; it does not manufacture permission that was never there.

WhatsApp is your best channel and your biggest liability

In Latin America, WhatsApp is where deals close. It is also where the largest pile of undocumented data sits, because numbers arrive from everywhere: typed in during a store visit, copied out of a group, exported from a 2021 order, bought in a list someone swears is clean.

Meta already requires opt-in for marketing templates, and since billing moved to per-marketing-template rather than per-conversation, blasting a dirty list is expensive twice over: you pay for every send and you collect blocks that drag your number's quality rating down. A low-quality number stops sending altogether. That is usually the moment the conversation stops being legal and becomes operational — and operational is when teams finally act.

What I'd do in the next 60 days

None of this needs a six-month program or a US$2,000-a-month platform. It needs one uncomfortable inventory:

  • List every live data source: forms, landing pages, giveaways, WhatsApp, POS, the rep's spreadsheet. Next to each one, write where the permission came from. The blanks are the finding.
  • Segment the CRM by source and by date of last verifiable consent. If you can't run that query, that's the answer.
  • Rewrite forms so the advertising purpose is stated specifically, and store the timestamp plus the exact wording each person agreed to. Without evidence you don't have consent, you have faith.
  • Fix the privacy notice. If it mentions INAI, change it today.
  • Set a retention rule. "Forever" is not a policy, and a 2019 list doesn't convert anyway.

The commercial case nobody makes

There's an upside argument here, not just a defensive one. A list built on explicit, dated consent performs better: higher deliverability, fewer blocks, cleaner signal for the bidding algorithms. Brands that went through GDPR in Europe didn't lose performance by pruning lists — they lost contact volume and gained response rate. Mailing 40,000 people who opted in costs less than mailing 180,000 who report you and burn your sending domain.

The opposite failure is just as common: treating compliance as a reason to stop measuring. We watched that happen with Apple's ITP, when half the region decided attribution was dead and quietly stopped optimizing for two years. The law requires you to have permission. It does not require you to go blind.

December is two months out. Whatever doesn't get inventoried now gets discovered in an audit or, worse, when an annoyed customer learns how to write a data subject request. Those emails are already landing in Latin America, and the first reply you send decides whether it closes or escalates.

#privacy#data#consent#latam#whatsapp